CVE-2017-13135: Libbpg Project Libbpg

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products, because the CUData::initialize function in common/cudata.cpp mishandles memory-allocation failure.

Affected products

Published 2017-11-16. Last modified 2026-06-17.